PT-2026-51811 · Jenkins · Owasp Zap Plugin
CVE-2026-57301
·
Published
2026-06-24
·
Updated
2026-06-24
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins OWASP ZAP Plugin versions prior to 1.0.8
Description
Build operations are performed on the Jenkins controller instead of the assigned agent. This allows attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
Recommendations
Update Jenkins OWASP ZAP Plugin to version 1.0.8 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Owasp Zap Plugin